CSIDB logo
Incident

Stadt Leuna

Incident posture

Attack window
Jul 2025
Location
Germany
Status
Resolved
CIA posture
Available to members
Updated
2026-08-27 02:41

Linked entities

Victim
Stadt Leuna
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2025
Discovered
Jul 2025
Disclosed
Aug 2025
Resolved
Jul 2025

Summary

The city administration's website suffered a distributed denial‑of‑service attack that rendered it inaccessible for several hours and caused lingering loading problems afterward. The attack targeted the central infrastructure of the service provider brain‑SCC Merseburg GmbH, which hosts the city's data and also serves other municipalities, prompting the provider to deploy dynamic filtering to block suspicious traffic and restore service. The provider confirmed that no data security risk occurred during the incident.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On 29 July 2025 the official website of the city of Leuna, www.leuna.de, became inaccessible starting in the morning and remained unavailable until the late afternoon. The outage was caused by a distributed denial of service (DDoS) attack that flooded the targeted infrastructure with excessive traffic, preventing legitimate users from accessing the site. The attack directed at the central infrastructure components managed by brain‑SCC Merseburg GmbH, the service provider contracted by the city administration to host its online services. Because brain‑SCC also provides hosting for several other municipalities, those entities experienced concurrent disruption.

Throughout the attack the affected web pages endured a sustained increase in server load, which persisted for several hours and resulted in slow or failed page loads even after the initial outage period. On the following day, 30 July 2025, users continued to report difficulties when attempting to load the city’s web pages, indicating lingering effects of the traffic surge. The service provider confirmed that at no point during the incident was there any risk to the confidentiality, integrity, or availability of the underlying data stored on its servers. No data breach or unauthorized access was reported as part of the DDoS event.

In response to the ongoing flood of traffic, brain‑SCC’s technical team implemented targeted countermeasures, including the deployment of dynamic filter mechanisms designed to detect and block suspicious IP addresses associated with the attack. These filters were adjusted in real time as malicious traffic patterns were identified, gradually reducing the volume of illegitimate requests reaching the web servers. By the late afternoon of 29 July 2025 the combined filtering and traffic‑shaping actions had succeeded in mitigating the DDoS pressure, restoring normal accessibility to the city’s website. The city administration subsequently issued an apology for the inconvenience caused by the temporary loss of online services.

Sources

Sources available to members: 1 source.

CSIDB